Regulatory brief · NIST AI RMF
Four functions, and the evidence each one asks for.
The NIST AI Risk Management Framework 1.0 is voluntary, sector-neutral, and the vocabulary almost every other AI framework borrows — including Treasury's financial-services adaptation. It is organised around four functions: GOVERN, MAP, MEASURE, MANAGE.
Why a voluntary framework matters here
NIST AI RMF creates no legal obligation. It matters because it became the shared vocabulary: Treasury's FS AI RMF is an explicit adaptation of it, and examiners increasingly frame questions in its terms.
Its practical value is that it separates stating a control from evidencing one. Most AI governance programmes are strong on GOVERN and MAP, which are documentation exercises, and thin on MEASURE and MANAGE, which require running systems that produce artefacts.
The four functions, and what we produce for each
| Function | What it asks | Evidence Sentinel produces |
|---|---|---|
| GOVERN | Accountability structures, policy, culture | Policy versioning; RBAC; governance-mode changes recorded with a named accountable owner; hash-chained audit |
| MAP | Context, inventory, use-case understanding | Model inventory with materiality tiering; agent classification; compliance tagging; Know Your Agent dossiers |
| MEASURE | Testing, metrics, evaluation | Disparate impact against the four-fifths rule; drift monitoring; monthly QA sampling with disagreement rate; release-gated eval sets |
| MANAGE | Risk response, prioritisation, remediation | Enforced guardrails; kill switches; escalation queue; governance modes for staged rollout |
Note where the weight sits. GOVERN and MAP we support with records. MEASURE and MANAGE are where an inline decision gate has something the documentation-first tools do not: the controls actually ran, and the artefact proving it is chained.
Scope, honestly
Mapping to a function is not conformance
We map capabilities to the four functions. We do not claim Sentinel makes an institution NIST AI RMF conformant — the framework covers organisational practices, workforce, and lifecycle decisions well outside what any single product touches. Treat this as the subset a decision gate can evidence.
Sources
Check every claim above. We would rather you did.
If we have characterised any of this incorrectly, tell us and we will correct the page.
Design partners
Start where the evidence is thinnest.
Most programmes can describe their governance and cannot evidence their measurement. A two-week shadow run produces the MEASURE artefacts before you commit to anything.